Skip to content
Snippets Groups Projects
Commit 50b06a2b authored by Nick Mathewson's avatar Nick Mathewson :game_die:
Browse files

make the description of tolen_asserts more dire

We have a CVE # for this bug.
parent 115782bd
Branches
Tags
No related merge requests found
o Major bugfixes (security)
- Fix a heap overflow bug where an adversary could cause heap
corruption. Since the contents of the corruption would need to be
the output of an RSA decryption, we do not think this is easy to
turn in to a remote code execution attack, but everybody should
upgrade anyway. Found by debuger. Bugfix on 0.1.2.10-rc.
corruption. This bug potentially allows remote code execution
attacks. Found by debuger. Fixes CVE-2011-0427. Bugfix on
0.1.2.10-rc.
o Defensive programming
- Introduce output size checks on all of our decryption functions.
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment